Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A Rust and Tauri desktop app began triggering Microsoft Defender’s Trojan:Win32/Wacatac.B!ml detection after a release. Its developer, Luan Silveira Macea, says comparing executable imports did not reveal the change; building and scanning versions across the commit history with git bisect led to the commit that added sodiumoxide for account-file encryption. That points to a possible contextual false positive in this one case—not proof that libsodium is unsafe or that crypto libraries generally cause antivirus alerts.
What happened in this Tauri app
Macea’s RAM (Roblox Account Manager) is a Windows desktop application built with Rust, Tauri 2, and React. It manages multiple Roblox accounts, launches multiple game clients, and automates tasks such as rejoining servers. After a release, the author says the executable received Microsoft’s Trojan:Win32/Wacatac.B!ml detection. The reported VirusTotal result was 1/75, with Microsoft as the detecting engine. Macea’s incident report on DEV Community is the primary account; a WPS page mirrors that account, rather than providing an independent investigation.
The author first compared the last executable he considered clean with the flagged one using pefile. He found the same 16 imports he considered heuristically heavy, the same section entropy and linker, and four additional imports he regarded as ordinary file or message operations. That inspection did not identify the change associated with the detection, and his initial theory—that the model had simply changed its mind—was wrong.
Recommended Free Tools
How bisection found the commit
Instead of inferring the cause from the executable differences, Macea built versions across the project’s commit history, scanned them, and marked each result good or bad in git bisect. He reports that this process traced the first flagged build to the commit that integrated account-file encryption with sodiumoxide, Rust bindings to libsodium.
#1 Best Overall
- ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
The author’s explanation is that statically linked native cryptographic code, in an application that also manages credentials and automates processes, may have contributed to a heuristic model’s judgment. The detector’s internal reasoning is not established by the account. Macea explicitly does not blame libsodium itself; one project’s timeline cannot establish that the library is malicious or that it generally causes detections.
The practical lesson is about diagnosis: binary inspection can help describe what changed, but it may not isolate which source change correlates with an alert. In this incident, building and scanning intermediate revisions gave the author a more useful lead than reasoning from imports alone. Macea summarized the lesson: “Bisect, don’t theorize. My careful import-table analysis pointed at the wrong conclusion. A few rounds of git bisect pointed at the right commit.”
Rank #2
- ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
- TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
- ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
- REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
- DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
How to investigate a similar alert
- Record the exact artifact and result. Note the file’s identity or hash, the scanner, its detection name, and when the scan ran. A result belongs to the specific file and scanner snapshot; avoid treating “flagged” or “clean” as timeless properties of an entire project.
- Compare the last known clean build with the first flagged one. Inspect binary changes, imports, packaging, and build configuration as clues. Do not treat an apparently ordinary import table as proof that no relevant source change occurred.
- Build and scan intermediate revisions. Identify a commit known to produce a clean artifact and one known to produce a flagged artifact. Use
git bisectto narrow the interval, building and scanning each revision as needed. The result is only as informative as the consistency of the build and scan procedure. - Keep scanner results separate. Macea says a build passed local
MpCmdRunwhile VirusTotal’s Microsoft engine still flagged it. Record local Defender and hosted results independently instead of combining them into one verdict. - Make scan failures visible. The author reports that his earlier automation had failures in both the Defender step and VirusTotal verdict handling. A failed scan must not be reported as a clean result; scripts should distinguish clean, detected, and scan-error outcomes.
Replacing encryption without losing existing files
Once the sodiumoxide integration was identified, changing cryptographic code was not just a matter of making new encryption work. Existing users already had encrypted files, so the replacement needed to decrypt data written by the old implementation. A mismatch in derivation parameters or ciphertext layout could leave those files inaccessible even if new-code encryption and decryption worked correctly together.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteMatch the old format and parameters
Macea says the replacement used the pure-Rust crates argon2, crypto_secretbox (XSalsa20-Poly1305), and sha2, with parameters chosen to match the previous implementation. The reported Argon2 settings were version 0x13, time cost 6, memory cost 128 MiB, parallelism 1, and a 32-byte output. The account says crypto_secretbox retained the same MAC-before-ciphertext layout as libsodium.
Rank #3
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Those details describe this application’s compatibility target, not universal settings to copy into another system. When replacing a cryptographic implementation, verify the format and parameters actually used to produce the persisted data.
Test with data from the old implementation
The author created a fixture from bytes encrypted by the previous implementation and tested that the new code decrypted it to the expected plaintext. This checks an important property that a round-trip test alone cannot: new code can encrypt and decrypt its own output while still being unable to read users’ existing ciphertext.
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Performance and reported scan outcomes
The figures below are Macea’s reported observations for his project, not independently reproduced measurements or guarantees about other builds. Scan counts are snapshots for the artifacts and engines tested; they can change with the file, scanner, and time.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
| Artifact or measurement | Before replacement | After replacement |
|---|---|---|
| App executable | 1/75 on VirusTotal, with Microsoft reporting Wacatac.B!ml |
0/75; the author also reported Defender clean |
| MSI installer | 0/61; the author says it required administrator privileges | 0/75; the author says it was per-user and did not require admin |
| NSIS setup | 3/71 | 1/75; one generic ML engine identified the packager, according to the author |
| Argon2 derivation | 5.4 seconds in a debug build | 0.3 seconds optimized |
| Rust test suite | 230 seconds before dependency optimization in the dev profile | 41 seconds afterward |
The performance figures are project-specific: the article attributes them to Macea and does not present them as a controlled comparison applicable to other machines or workloads. The author says the Cargo dev-profile change optimized dependencies while leaving the application crate unoptimized.
Quick Recap
Best Value
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
What this incident does—and does not—show
- It shows how one developer traced a Windows detection to a commit that added cryptographic functionality, after an initial binary comparison failed to locate the relevant change.
- It does not establish why Microsoft’s model made its classification, that libsodium or
sodiumoxideis malware, or that replacing native crypto with pure Rust will prevent future detections. - It shows why persisted encrypted data needs a legacy-data compatibility test when the implementation changes.
- It shows that local and hosted scanner results can disagree in a particular case, so release checks should preserve which scanner tested which artifact.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

